Skip to content
ASIRI
← All articles

registers

Publishing your privacy notice

How your notice is built from the records you already keep, what happens when those records change, and how it reaches your website.

Abraham Esandayinze Tanta

Founder/CEO

Published Updated
privacy-policy

Your privacy notice is not a document you write here. It is assembled from the records you already keep — your activities, the grounds you rely on, your processors, your transfers, your retention rules — and every paragraph names the records it came from.

That is the whole idea. A notice written by hand sits beside your register as a second copy of the same facts, and the second copy is the one that goes stale. A notice assembled from the register cannot drift from it without saying so.

Building one

Record who your company is first, under Settings → This entity. The legal name, the RC number, the address, and an address people write to about their data. Until that is there, the first section of every notice comes back unwritten — a notice that cannot say who is speaking is not a notice.

Then Policies & notices → New document, and on the document itself, Assemble it from the registers.

Sections it will not write

Where your registers hold nothing, the section is left out and tells you why — "no transfer out of Nigeria is recorded", "no processor is recorded".

This is deliberate. The alternative is the sentence every template produces when it has no facts: *"we may share your data with third parties where necessary."* That reads as complete and says nothing, and it hides the gap it is standing in. An empty section is a gap you can close by recording the thing.

Changing the words

You can rewrite any section. Once you do, it is yours: Asiri stops refreshing it, and it is marked Your wording.

When a record behind a section you wrote later changes, you are told rather than corrected. You will see what the registers say now beside what you wrote, and you choose — take the new wording, or keep yours. Keeping yours is an answer, not a dismissal: it records that you read the change and decided your sentence still stands.

Publishing, and versions

Publishing puts a version in force. It does not change what people were shown before: the earlier version stays on the record, because what your notice said on a given day is the question a complaint turns on.

To change a published notice, raise a new version. The published one keeps serving the whole time you work on the new one, and nothing changes for anybody reading it until you publish.

Getting it onto your website

Open the document and look for Putting it on your website. It gives you a link and a snippet, both with your own address in them.

Use the link if you can. It needs no JavaScript, it is what a regulator will archive, and it keeps working even when Asiri does not — your notice is written out as a file, and your website reads that file rather than asking us for it.

Either way, publishing a new version updates what people read. There is nothing to change on your website afterwards.

"Published, and not yet reachable"

You may see this on a document you have just published. It means the register has your new version in force and the file has not been written out yet.

It usually clears within a couple of minutes. Until it does, people visiting your address read the previous version — which is the honest thing for us to tell you, rather than reporting success and letting you find out from a customer.

What Asiri does not tell you

Whether your notice is legally sufficient.

Assembling it from your records makes it true about your processing, which is a real and unusual thing and is not the same as legally sufficient. That is a judgement, and the only answer this register gives is the name of whoever made it: use Record who checked it to note the lawyer or firm who read it, and the date. Until somebody has, the document says so plainly.

privacy-policy

About the author

Abraham Esandayinze Tanta

Founder/CEO

Founder, Asiri — compliance infrastructure for Nigeria's NDPA · Creator of ndpr-toolkit (open source) · Security engineering → privacy tooling

More articles →

Ready to put the ideas into practice? Try the readiness check.